windows cannot backup one or more private keys because the csp does not support key export


hi,

i'm in process of changing our ca can issue sha256 certificates instead of "only" sha1 certificates.

however. step 1 ca, , step fails.

from within certificate authority mmc, try start backup:

but fails:

ok. maybe private key missing? how tell?

i have following ca certs:

if @ corresponding certs in certificate manager on ca (local computer/trusted root certification authorities), can find certs via thumbprint.

certificate #3 definitively have private key - i'm able export cert .pfx file.

any idea happened previous private keys? ca may unable create correct crls without previous private keys. if dont have access old keys anymore, can change the hkey_local_machine\system\currentcontrolset\services\certsvc\configuration\pdc-certificateauthority\cacerthash value remove old thumbprints , replace hypen this:

-
-
-
-
ba 01 61 3a 4c 6e 9e 84 bb 6b 72 19 89 77 47 48 4a 02 0d ba

stop , restart ca read value. recommend backing up/exporting registry key ca prior changes.


mark b. cooper, president , founder of pki solutions inc., former microsoft senior engineer , subject matter expert microsoft active directory certificate services (adcs). known “the pki guy” @ microsoft 10 years. co-founder of revocent (revocent.com) , certaccord product offers linux certificate enrollment microsoft ca. connect mark @ https://www.pkisolutions.com



Windows Server  >  Security



Comments

Popular posts from this blog

Group Policy Event ID 1058 Error Code 1326 (The user name or password is incorrect)

Suspicious event log Event ID: 4905

DCOM received error "2147746132" from...